Request for Proposal: Provision of Internal Audit Services to ITPC

Request for Proposal: Provision of Internal Audit Services to ITPC. Deadline: 16:00 SAT, 17 December 2021.

Request for Proposal: Provision of Internal Audit Services to International Treatment Preparedness Coalition (ITPC Global)

RFP Number: ITPC/IAS/RFP/11/2021

For a PDF version, click here. 

About ITPC

ITPC is a worldwide network of community activists united by our vision of a longer, healthier, more productive life for people living with HIV and/or AIDS (PLWHA). ITPC’s mission is to enable communities in need to access HIV treatment. ITPC was formed in 2003 at a historic meeting of 125 HIV treatment activists, mostly from the global south, that took place in Cape Town, South Africa.

In 2005, ITPC registered as a company limited by guarantee. It was incorporated in Botswana under the Botswana Companies Act. Until 2018 the Botswana entity has been operating as the Global office.

In 2016, ITPC registered as a not-for-profit organisation incorporated under the Companies Act of South Africa. 

ITPC operational budget and expenditure for FY 2019 was around $ 5,3 million and for FY 2020 was $4.3 Million. The 2021 FY Operational expenditure is projected to be $ 6.2 million.

ITPC current main programme areas are around:  HIV-advocates for treatment access across the globe through the focus of three strategic priorities:

  • Treatment education and demand creation (#TreatPeopleRight)
  • Intellectual property and access to medicines (#MakeMedicinesAffordable)
  • Community monitoring and accountability (#WatchWhatMatters)



The purpose of this request is to appoint a suitable independent Internal Audit Service Provider that can provide and maintain an appropriate Internal Audit Service to ITPC and to the Finance, Audit and Risk Committee (FRAC) of the Board of ITPC.

Role and Objectives of The Internal Audit Service

The Internal Audit Service should be an independent appraisal function within ITPC, which provides management with a systematic review and evaluation of the operations for determining the economy, efficiency and effectiveness of policies, procedures, practices and the overall system of internal control within the Institute.

The objective of the Internal Audit Service is to add value by assisting the FRAC and Management in effectively discharging their responsibilities, including the promotion of effective internal controls at reasonable cost as well as compliance with the provisions and requirements of a number of different donors.

Organisational Status of Internal Audit

The internal auditor will report to the Finance, Risk and Audit Committee (FRAC) functionally and to the Executive Director administratively, and will promote and ensure:

  • the independence of internal audits;
  • broad audit coverage: 
  • adequate consideration of audit reports; and
  • the implementation of audit recommendations


Scope of The Internal Audit Work

The internal audit must be conducted in accordance with the standards for the Professional Practices of Internal Auditing and the Code of Ethics set by the Institute of Internal Auditors (IIA).

The scope of Internal Audit work shall consist of, but not limited to the following work: 

  • The evaluation of the adequacy and effectiveness of the organisation’s corporate governance processes, risk management, and internal control systems and the quality of performance in carrying out assigned responsibilities to achieve the organisation’s stated goals and objectives
  • Review and update the internal audit charter for approval
  • Reviewing the reliability and integrity of financial and operational information and the means used to identify, measure, classify and report such information;
  • Reviewing the systems established by management to ensure compliance with applicable ITPC policies, donor regulations, plans, procedures and Acts, and to determine whether the organization is in compliance;
  • Reviewing the means of safeguarding assets and verifying the existence thereof;
  • Appraising the economy and efficiency with which resources are employed, and identifying and recommend opportunities to improve operating performance;
  • Reviewing operations or programmes to ascertain whether results are consistent with established objectives and goals, and whether the operations or programmes are being carried out as planned, i.e. performance audits;
  • Reviewing the planning, design, development, implementation and operation of all major computer-based systems of ITPC to determine whether:
  • Adequate controls are incorporated in systems;
  • Thorough systems testing is performed at appropriate intervals;
  • System documentation is complete and accurate; and that
  • User needs are met.
  • IT systems are compliant with the new POPI Act on storing personal information
  • Reporting to the FRAC in writing on the scope of reviews of corporate governance on any significant findings and meeting the deadlines as agreed to with ITPC FRAC.


Scope of Internal Audit Services

The appointed service provider will be required to:

  • Compile a three-year risk based rolling internal audit plan for approval by the FRAC.
  • Develop a detailed annual plan, to be approved by ITPC every year, indicating scope for each internal audit.
  • Discuss audit coverage with management and the FRAC 
  • Perform internal audits in compliance with the International Professional Practices Framework (IPPF).
  • Monitor the clearing and implementation of the external auditor’s audit findings and recommendations.
  • Report on the findings to management and secure comments before presenting to the FRAC.
  • Attend FRAC meetings when requested, and provide feedback on internal audits completed, the management of risks including a regular overview of the control environment.
  • Provide overall annual opinion on the audited control environment for the FRAC. 
  • Work closely with the external auditors and other assurance providers to ensure synergy of approach, with a view to minimal duplication of effort and to obtain reliance on work performed
  • Perform compliance reviews with the:
  • Financial, procurement and human resources policies of ITPC
  • Donor financial and procurement requirements 
  • Corporate Governance & Compliance 
  • Information Technology 
  • King IV Report, where practicably possible.
  • Any other statutory and regulatory requirements.



Provide management reports with management letter points for each respective area of the business audited in line with the audit plan;

Based on observations made during the course of the audit(s), provide recommendations in the management letter(s) for the audit findings and any weaknesses in internal controls for improvement or efficiency;

Provide audit summary memorandums and other progress reports to the FRAC after the completion of each planned audit;

Submit to the FRAC or the Board of ITPC, reports after the completion of any ad-hoc audits or assignment;

Report to the FRAC on major issues encountered during any audit or assignment undertaken;

Report on any issues that have arisen during the course of the audit which could appear to have a material impact, or potential impact, on the business and/or the financial statements for each year under review.

Fees and Payment

Proposed fee structure based on the following:

  • Total annual hours
  • Average hourly rate
  • Reimbursement costs such as telephone, travel, stationery and printing


Content of The Technical and Financial Proposal

The proposal should indicate:

  • All relevant perceived strengths and weaknesses of the firm bidding for the services e.g. similar previous experience, in-house skills, providing information which will assist ITPC to assess its capabilities, capacity, competitive advantages, etc.
  • A proposed plan of action to achieve the objectives of the internal audit function and risk management support to management. Such plan should cover short- and medium-term steps to manage the internal audit function and the risk management effort for ITPC;
  • Copies of appointment letters of previous and current internal audit contracts awarded;
  • An organogram or list of partners, managers, specialists and assistants together with the curriculum vitae of the staff who will be available for the duration of the contract with ITPC. In addition, the team to be appointed to provide internal audit services to ITPC should:
  • Appoint a team, the core of which should remain constant for the duration of the of the contract
  • Source external expertise if and where necessary, based upon the annual risk assessment, the three-year rolling risk based internal audit plan or any other relevant factor.
  • Any possible staff changes during the course of the audit must be done in consultation with ITPC;
  • In so far as possible, provide an overview of the methodology to be applied to the execution of the internal audit function.


The service provider must supply the following information:

  • Certification of registration (CIPC)
  • Valid original tax clearance certificate/SARS compliance Pin
  • Copies of registration and endorsement from relevant internal audit local and or international boards.
  • Company ownership status
  • Organisational chart for the firm
  • Company Profile


Validity of Proposals

The Service Provider is required to confirm that it will hold its proposal valid for 90 days from the closing date of the submission of proposals, during which time it will maintain without change the personnel proposed for the service together with their proposed rates.

Appointment, Commencement and Duration

The successful Service Provider will sign a legal agreement with ITPC which will be valid for three years subject to confirmation on an annual basis by the FRAC of ITPC based on an evaluation of the effectiveness as well as the independence and objectivity of the internal auditors.

The successful Service Provider will have unlimited access to all appropriate information of ITPC required to execute the internal audit function within the normal working hours of the organisation.

Description and Extent of Work

  • Conducting of audit assignments
  • Assignments are to be performed in accordance with the Service Provider’s internal audit procedures in compliance with the standards set by the IPPF. However, each assignment should consist of the following tasks:
  • Audit preparation (which should include the scoping document audit plan)
  • Preliminary survey
  • Review of internal controls
  • Audit testing
  • Development of findings and recommendations
  • Obtaining management responses; and
  • Reporting

On request from ITPC and the FRAC, all procedural documentation and working papers must be made available within three (5) working days, even after the expiry of the appointment.

Timing of assignments

The annual internal audit coverage plan shall be presented and agreed to by ITPC management and FRAC at its meeting before the commencement of any work. Furthermore, the final responsibility of approving the scope and extent of the work resides with the FRAC.

Quality assurance reviews of the work

The internal audit shall ensure that all work conforms to the standards for the Professional Practice of Internal Auditing (Institute of Internal Auditors). Such work shall further be subject to an external quality assurance as may be considered necessary and appropriate by the FRAC.

Independence and objectivity of audit staff

In carrying out the work, the internal auditor must ensure that their staff maintains their objectivity by remaining independent of the activities they audit,

Monitoring progress of assignments

The internal auditor shall present a report on the progress of the internal audit work at the scheduled FRAC meetings, and to the Executive Director of ITPC as and when required to do so.

Report of audit results

The report(s) on findings and recommendations should be sent to the Executive Director of ITPC and departmental heads responsible for implementing those recommendations (auditee) for their consideration and comments. Within ten (10) working days of sending the report(s), the internal auditors shall meet with the auditee to discuss the findings and obtain written responses to the recommendations together with implementation dates. These shall then be incorporated into the final report which must be issued to the Executive Director. Copies of these reports must also be tabled at the FRAC meeting for discussion.

The structure of the report is to be as follows:

  1. Introduction
  2. Audit objective and scope
  3. Background
  4. Executive summary
  5. Activity, findings, recommendations and management response (including corrective action and implementation dates)
  6. Conclusion
  7. Practical method of proceeding with recommendations


Fraud and irregularities

In planning and conducting work, the Service Provider should seek to identify serious defects in the internal controls which might result in possible malpractices. Any such defects must be reported immediately to the Executive Director and the FRAC without disclosing these to any other members of the staff. This applies to instances where serious fraud and irregularity is uncovered.

Authorised delegate(s)

Nothing stipulated in the task directives may be amended without the written confirmation of the Executive Director of ITPC or any person nominated by him/her.

Proposal Evaluation

In broad terms, ITPC will assess proposals on the basis of the technical and financial criteria indicated above, to ascertain value for money, along with any other specific criteria that may be deemed pertinent during the selection process. The success of the bid will be determined by the ability of the firm to competently execute this assignment. The technical and financial components of the written proposal must be submitted in hard copies to the address listed below.

In more specific terms, the following assessment criteria would be used to evaluate proposal.

  • Credentials of Management Team
  • Audit methodology (including quality assurance)
  • Continuing professional experience
  • Track record & experience
  • Previous experience in NPO sector (with grant funding) of the envisaged audit team
  • Previous experience in clients similar to ITPC
  • Ability to meet the company requirements
  • Price

ITPC reserves the right not to accept any proposal and/or proposal with the lowest price.

Condition for Proposals

Only electronic submission via email will be accepted.

Proposals received after the set time (16h00) will be disqualified.

The Service Provider must include a cover letter clearly stating the name of the firm and name; address and telephone number of the Service Provider’s representative.

The Service Provider shall furnish such additional information that ITPC may reasonably require.

ITPC will not be liable for any cost incurred in the preparation of the proposal.

ITPC may invite Service Providers for an oral interview/ presentation prior to the approval of a proposal; however, ITPC will not be liable for the costs incurred by the Service Provider in connection with such interview or presentation.

ITPC will keep the contents of the application strictly confidential.

The information/data provided in this document, together with any subsequent issue of addenda of information/data is given in good faith for guidance of applicants. No warranties or representations are given regarding accuracy or completeness of such information.

Submission of Proposals

Closing date: 17 December 2021

Time: 16h00

Submissions to be Emailed   

Service providers are at liberty to discuss and seek clarity to any aspect of this request for proposal with the entity and enquiries must be referred to: 

ITPC does not take any responsibility for any procedural and substantive information obtained from a source other than the above-mentioned official. For more information about ITPC see website: 



Service Providers who do not have a fully resourced office in Pretoria or Johannesburg, will not be considered.

More from 


Together, we can do more!

Whether you’re a philanthropist looking to make a one-time contribution or an institutional donor interested in providing on-going support, every dollar counts! We can carry out this strategic plan faster and reach even further with you as a significant force propelling us forward.

Donate here